Quantcast
Channel: Questions in topic: "heavy-forwarder"
Viewing all articles
Browse latest Browse all 727

Heavy forwarder isn't forwarding data from UDP port to indexer

$
0
0
Hello team, I have a HF in place and it is supposed to listen to a UDP port and forward the data to the indexer. Its confirm the netstat shows UDP port open and also network Team confirms for the port receiving data. But the splunk below configurations are not successful: /opt/splunk/etc/system/local/inputs.conf [udp://1049] index=abc sourcetype=efg disabled = 0 outputs.conf having indexer conf splunkd.log shows only one entry for port as INFO TcpInputProc - Closing raw IPv4 port 1049 Please help on this to make the instance listen to UDP port.

Viewing all articles
Browse latest Browse all 727

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>